Spotnana
Security Architecture and Compliance Framework for Spotnana
Pages
9
Time to read
5 mins
Language
English
Pages
9
Time to read
5 mins
Language
English
This document is a security whitepaper that outlines the security architecture and compliance measures implemented by Spotnana for its Travel-as-a-Service (TAAS) platform. It details the secure design principles, including tenant isolation and role-based access control, which ensure that customer data is logically segmented and access is managed effectively. The document describes the secure architecture that protects against denial of service and web application attacks, highlighting the use of Amazon Web Services (AWS) for infrastructure management. It also explains the measures taken for data protection both in transit and at rest, emphasizing encryption practices and environment segregation. Additionally, the whitepaper discusses the secure software development lifecycle (SDLC), deployment processes, and internal access controls. Compliance with ISO 27001:2022 and SOC2 Type 2 standards is documented, along with the use of a PCI-compliant third-party service provider for payment processing. The paper concludes with an overview of the continuous compliance monitoring program and third-party audits to maintain security standards.